preprint Open access

OAuth Is Not Enough Authorization Challenges for Autonomous AI Agents

Research footprint

At a glance

Citations
0
References
0
Comments
0
Paper overview

Öz

Recent publications on AI Agents are anchoring on OAuth, specifically OAuth 2.1, for delegated access. The paper identifies key limitations of OAuth in this context, including coarse permission scopes, lack of dynamic policy enforcement, and insufficient support for multi-hop delegation of authority. It then proposes complementary mechanisms such as policy-as-code enforcement, enhanced token delegation flows, and secure AI agent architecture patterns to address these gaps. This approach aligns with emerging industry standards and research, maintaining compatibility with existing OAuth infrastructure, while extending it to ensure AI agents act within human-intended bounds. The analysis concludes that securing AI agents requires a layered authorization stack that extends beyond OAuth alone.

Record transparency

Publication details

DOI
10.36227/techrxiv.174952577.74018032/v1
OpenAlex
W4411192816
Document type
preprint
Language
EN
Last metadata update
Community

Comments

Oturum Açın to join the discussion.

  1. No comments yet. Start the discussion.